CVE-2026-54660 | acacode swagger-typescript-api up to 13.12.1 Remote Schema Resolution resolved-swagger-schema.ts getRemoteRequestHeaders/warmUpRemoteSchemasCache authorizationToken cross-domain policy
A vulnerability has been found in acacode swagger-typescript-api up to 13.12.1 and classified as problematic. This affects the function getRemoteRequestHeaders/warmUpRemoteSchemasCache of the file src/resolved-swagger-schema.ts of the component Remote Schema Resolution. Performing a manipulation of the argument authorizationToken results in permissive cross-domain policy with untrusted domains.
This vulnerability is reported as CVE-2026-54660. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More